Skip to main content

Security Training Catalogue

Interactive 3D exercises across phishing, GDPR compliance, the EU AI Act, OWASP Top 10 for LLM & Agentic AI, OWASP Privacy Risks, and real-world incident case studies. Free to play, no sign-up required.

Security Awareness

70 exercises · Build a security-first culture with interactive exercises covering phishing, social engineering, device security, and more.

Privacy & Compliance Frameworks

37 exercises · Master GDPR, the EU AI Act, and OWASP privacy risks with hands-on exercises covering data protection, breach response, AI governance, and privacy by design.

AI & LLM Security

21 exercises · Prepare for AI-powered threats including prompt injection, deepfake attacks, and LLM manipulation.

Prompt Injection Attack

Stop a hidden prompt from hijacking your AI assistant mid-task.

  • Detect hidden instructions embedded in documents processed by AI
  • Trace how injected prompts override legitimate AI behavior
  • Apply safe document handling before feeding content to AI tools
Play Exercise

AI Training Data Poisoning

Watch poisoned documents corrupt your AI's answers in real time.

  • Trace how manipulated documents alter AI-generated outputs
  • Identify signs of data poisoning in AI responses
  • Apply content integrity controls to knowledge base inputs
Play Exercise

Sensitive Data Exposure Through AI

See what happens when confidential data enters a consumer AI tool.

  • Recognize sensitive data categories that should never enter AI prompts
  • Trace how pasted content persists in AI training data and logs
  • Apply data classification policies before using AI tools
Play Exercise

AI System Prompt Extraction

Extract hidden instructions from a customer-facing AI chatbot.

  • Execute prompt extraction techniques against a live AI chatbot
  • Identify sensitive information exposed through leaked system prompts
  • Apply prompt hardening techniques to prevent system instruction disclosure
Play Exercise

AI Agent Goal Hijacking

Stop an autonomous AI agent from being redirected by a poisoned email containing hidden instructions.

  • Detect hidden instructions embedded in incoming data that redirect agent objectives
  • Trace how a goal-hijacked agent pivots from legitimate tasks to data exfiltration
  • Apply input validation strategies that prevent agents from treating data as instructions
Play Exercise

Detecting a Rogue AI Agent

Investigate a compromised AI agent that appears functional while silently performing unauthorized actions and evading monitoring.

  • Detect covert unauthorized actions performed by an agent that appears to be operating normally
  • Trace persistence mechanisms that allow rogue agents to survive restarts and monitoring sweeps
  • Apply behavioral analysis and anomaly detection to distinguish rogue agents from legitimate ones
Play Exercise

Real-World Incidents

2 exercises · Learn from actual security breaches. Walk through the MGM Resorts attack, BEC fraud cases, and more.

The Developer Track

Application security split by attack surface. Free, hands-on, no sign-up.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.